FINDING · DETECTION
The GFW performs no stateful TCP stream reassembly, inspecting one packet at a time: splitting the blocked keyword '?falun' across two TCP segments is sufficient to evade detection entirely. Cross-device state is also absent — triggering a block on one border AS (e.g., AS9929) had no effect on traffic transiting a different Chinese border AS.
From 2006-clayton-ignoring — Ignoring the Great Firewall of China · §4.1 · 2006 · Privacy Enhancing Technologies
Implications
- Control-plane handshakes in circumvention protocols should span multiple TCP segments so any keyword-like bytes never appear in a single inspectable packet — this evasion is free if the transport already segments its greeting.
- Multi-homing or route diversity across different Chinese border ASes resets triggered block state and provides independent evasion paths.
Tags
Extracted by claude-sonnet-4-6 — review before relying.